-= Per source details. Do not edit below this line.=-
The package elf-stats-cocoa-ribbon-476 was found to contain malicious code.
The OpenSSF Package Analysis project identified 'elf-stats-cocoa-ribbon-476' @ 3.0.0 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"import_time": "2025-12-03T17:09:19.123168655Z",
"sha256": "4634f9dee93f806a074705a1dcdcb30d630fa3a68ea61bc2c2d4e9a9510128af",
"source": "ossf-package-analysis",
"modified_time": "2025-12-03T16:50:41Z",
"versions": [
"3.0.0"
]
},
{
"import_time": "2025-12-03T18:10:08.314502915Z",
"sha256": "005ed1613dc4777b86a0449d32f014ea40f1ab9237ebd84bed9d955cdbaefd56",
"source": "amazon-inspector",
"modified_time": "2025-12-03T17:50:51Z",
"versions": [
"3.0.0"
]
},
{
"id": "RLMA-2025-06157",
"import_time": "2025-12-23T19:07:09.707482855Z",
"sha256": "c3e45078cc17d31dbc0ad1610fd24596140225c8e74bcdb6f861a20b39ec0df2",
"source": "reversing-labs",
"modified_time": "2025-12-23T08:07:01Z",
"versions": [
"2.0.0",
"3.0.0"
]
}
]
}